Lead PCI DSS Consultant / Qualified Security Assessor (QSA)
Golden Tech and Services, LLC is seeking an experienced Lead PCI DSS Consultant, Qualified Security Assessor, or authorized representative of an established PCI compliance consulting firm for an anticipated higher-education compliance engagement.
This is a contract-contingent opportunity. Selection does not guarantee employment or an assignment. Any engagement will depend on contract award, final client requirements, approval of proposed personnel and subcontractors, and execution of an appropriate consulting, subcontracting, teaming, or joint-venture agreement.
About Golden Tech and Services
Golden Tech and Services, LLC is a New York State- and New York City-certified Minority-Owned Business Enterprise providing cybersecurity, cloud, information technology, professional consulting, and training services.
We are developing a qualified team to support a potential multi-year Payment Card Industry Data Security Standard compliance engagement involving a large public higher-education system with multiple campuses and merchant environments.
Position Summary
The selected consultant or consulting partner will help assess, improve, and maintain PCI DSS compliance across complex payment-card environments. The work may include gap assessments, remediation guidance, policies and procedures, training, merchant-account support, payment-gateway evaluation, third-party compliance reviews, and ongoing advisory services.
The anticipated contract term is three years, with two optional one-year renewals. Workload, schedule, onsite expectations, and start date will be determined by the final client requirements.
Responsibilities
- Conduct PCI DSS gap analyses across cardholder data environments.
- Review payment-card devices, network infrastructure, security controls, system inventories, network diagrams, and payment-data flows.
- Perform control observation, testing, review, and validation.
- Identify compliance risks and develop practical remediation recommendations.
- Develop and update PCI DSS policies, procedures, checklists, and training materials.
- Support Self-Assessment Questionnaires, Attestations of Compliance, Reports on Compliance, third-party service-provider reviews, and other PCI compliance documentation.
- Review merchant accounts, merchant IDs, payment gateways, processors, and payment solutions.
- Assist with onboarding, configuration, testing, maintenance, and troubleshooting of payment systems.
- Evaluate card-present, online, and mobile payment solutions.
- Recommend validated P2PE, tokenization, EMV, NFC, and other PCI scope-reduction solutions.
- Review internal and external vulnerability-scanning processes and resulting remediation activities.
- Review third-party agreements for appropriate PCI DSS requirements.
- Develop reusable templates and maintain version-controlled compliance documentation.
- Prepare management reports, technical findings, project updates, meeting summaries, and other required deliverables.
- Provide PCI DSS training and ongoing advisory support to technical and nontechnical stakeholders.
- Participate in meetings and coordinate with university, technology, finance, procurement, and merchant stakeholders.
Mandatory Qualifications
Applicants must demonstrate the following qualifications individually or through the consulting firm they are authorized to represent:
- At least 10 years of relevant experience providing PCI DSS compliance consulting services.
- Extensive knowledge of current PCI DSS requirements, including PCI DSS 4.x.
- Demonstrated experience conducting PCI DSS assessments, gap analyses, control validation, and remediation planning.
- Experience supporting complex organizations with multiple merchants, campuses, business units, or payment environments.
- Ability to provide at least three relevant client references who may be contacted.
- Ability to provide at least two higher-education references involving similar PCI DSS or payment-security services.
- Experience with SAQs, AOCs, ROCs, third-party service providers, payment gateways, vulnerability management, P2PE, tokenization, and payment-security controls.
- Authorization to perform professional consulting services in New York State.
- Ability to provide documentation verifying all claimed credentials and the qualifications of proposed key personnel.
- Ability to comply with confidentiality, cybersecurity, privacy, background-screening, and data-protection requirements.
- Strong written, verbal, technical, training, and stakeholder-management skills.
Preferred Qualifications
- Active Qualified Security Assessor credential issued through the PCI Security Standards Council.
- Employment by or affiliation with a PCI SSC-recognized Qualified Security Assessor Company.
- Experience serving colleges, universities, government agencies, or public-sector institutions.
- Experience with decentralized or multi-campus merchant environments.
- Knowledge of FERPA, the Gramm-Leach-Bliley Act, applicable privacy requirements, and government cybersecurity standards.
- Relevant credentials such as QSA, PCIP, ISA, CISSP, CISA, CISM, CRISC, or comparable certifications.
- Experience evaluating payment gateways, merchant processors, P2PE solutions, tokenization, EMV, NFC, e-commerce, and mobile-payment technologies.
- Professional liability, errors-and-omissions, cyber, security, and privacy insurance coverage of at least $1 million per occurrence.
Engagement Details
- Job type: Contract
- Compensation: $90–$150 per hour, depending on qualifications, role, responsibilities, approved client budget, and final agreement
- Schedule: Hours will vary based on project needs
- Location: Hybrid or remote, subject to final client requirements
- Contract term: Potential three-year engagement with two optional one-year renewals
- Engagement may be structured as an individual consulting agreement, subcontract, teaming arrangement, or other mutually acceptable relationship
Compensation is contingent on contract award and does not represent guaranteed hours, revenue, or employment.
How to Apply
Individual consultants should apply directly through Indeed and provide:
- A current résumé
- Current PCI DSS and cybersecurity credentials
- A summary of relevant PCI DSS experience
- Details of higher-education or government experience
- Availability and proposed hourly rate
Authorized representatives of established PCI DSS or QSA consulting firms may also apply through Indeed. Firm representatives should provide:
- A company capability statement
- Total years of organizational PCI DSS experience
- PCI SSC company and personnel credentials
- At least three relevant client references, including two higher-education references
- Proposed project team and key-personnel résumés
- Preferred engagement structure
- Proposed hourly, monthly, or project-based pricing
- Evidence of applicable insurance, if available
Additional firm documentation may be emailed to [email protected] using the subject line:
PCI DSS/QSA Consulting Partner – [Applicant or Firm Name]
Equal Opportunity
Golden Tech and Services, LLC considers qualified applicants and business partners without regard to race, color, religion, sex, pregnancy, national origin, age, disability, veteran status, sexual orientation, gender identity, or any other status protected by applicable law.
Pay: $90.00 - $150.00 per hour
Work Location: Hybrid remote in New York, NY 10030